# Error in logstash-plain-logs in /applog/logstash

**URL:** <https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260>\
**Category:** Logstash\
**Created:** [October 4, 2024, 4:22pm UTC](https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260 "2024-10-04T16:22:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohit\_dhiman](https://avatars.discourse-cdn.com/v4/letter/r/34f0e0/32.png) [@rohit\_dhiman](https://discuss.elastic.co/u/rohit_dhiman)\
**Post date:** [October 4, 2024, 4:22pm UTC](https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260/1 "2024-10-04T16:22:47Z")

</div>

Hello All,

We are getting below error in the logstash-plain-logs in /applog/logstash

Below are the complete logs.

```auto
[logstash.outputs.opensearch] [main] [2cd0b680af9b49acc4d5ae414a3665aabb9aa76a58d0430b62230cc5c2e971bc] Could not index event to
OpenSearch. (:status=>400, :action=>["index", (:_id=>nil,:_index=>"mulesoft-logs-2024.10.04", :routing=>nil),
("contextMap"=>{"correlationId"=>"50e4b0092b4d", "processorPath"=>"proxy-api/processors/1"), "loggerFqcn"=>"org.apache.logging.slf4j.Log4jLogger", "@version"=>"1", "threadId"=>26387, "loggerData">("priority"=>"DEBUG", "correlationId"=>"48bc2bc1-7c9f-4407-a9e7-50e4b0092b4d", "category"=>"logging", "content"=> ("payload"=>"{\"tranid\": \" **********\",\"aggregatorVPA\": \"********** \",\"customerId\": \" ********** \")", "apiName"=>"/demo","httpStatus"=>0),"threadName"=>" (MuleRuntime].uber.1387: [proxy-api].proxy-api.Bl BLOCKING @6592d508",
"timestamp"=>"2024-10-04T14:00:14.6552", "environment"=>"uat", "tracePoint"=>"START", "elapsed"=>1, applicationVersion"=>"1.0.0-SNAPSHOT", "applicationName"=>"proxy-api",
" "message"=>"Start: proxy-api-payload", "locationInfo"=>{"fileName"=>"proxy-api.xml", "rootContainer"=>"proxy-api", "lineInFile"=>"34", "component"=>"json-logger: logger"}},
"appName"=>"proxy-api", "loggerName"=>"logging", "event"=>(), "apiName"=>"proxy-api",
threadPriority"=>5 " , "endOfBatch"=>true, "thread"=>"[MuleRuntime].uber.1387: [dreamll-olive-proxy-exp-api].dreamll-olive-proxy.BLOCKING @6592d508", "level"=>"DEBUG", "timeMillis"=>1728050414655, "@timestamp"=>2024-10-04T14:00:14.6552)), response=>("index"=>("_index"=>"mulesoft-logs-2024.10.04","type"=>" doc",
"_id"=>"C2ray472", "status"=>400, "error"=>("type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [loggerData.content] of type [text] in document with id 'C2ray47Z'. Preview of field's value: '(apiName=/demo,
payload=(\"tranid\": \" **********\",\"aggregatorVPA\": \"********** \",\"customerId\": \" ********** \"),
httpStatus=0)'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START OBJECT at 1:336")))))

```

Can someone please help why this error is occurring. Also what can we do to resolve it ?

Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 4, 2024, 4:50pm UTC](https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260/2 "2024-10-04T16:50:20Z")

</div>

That's an opensearch exception, but it looks very similar to a mapping exception that elasticsearch will produce. I suggest you read [this](https://discuss.elastic.co/t/logstash-errors-mapper-parsing-exception-vs-illegal-argument-exception/236783/3) thread and [this](https://discuss.elastic.co/t/problem-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch-wazuh-alerts-3-x-2020-05-30/235038/6) post. If those don't help then try asking in the [OpenSearch forums](https://forum.opensearch.org/).

---

<div class="post-metadata">

**Author:** ![rohit\_dhiman](https://avatars.discourse-cdn.com/v4/letter/r/34f0e0/32.png) [@rohit\_dhiman](https://discuss.elastic.co/u/rohit_dhiman)\
**Post date:** [October 10, 2024, 11:30am UTC](https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260/3 "2024-10-10T11:30:17Z")

</div>

Hi @Badger ,

Thanks for your inputs.

I have created a topic in opensearch.

Pinning the same question here as well.

Is there a way where we can retrigger the failed logs from logstash to opensearch ?

We know we can configure the dead letter queue but is there any other way apart from dead letter queue configuration.

Also, can we setup a predefined mapping schema in .conf file to resolve this issue.
